A popular open-source package with over one million monthly downloads has been found to steal user credentials. Developers urge immediate action.